ship-infrastructure-ci-cd

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several well-known GitHub Actions for workflow automation, including 'actions/checkout@v4', 'actions/setup-node@v4', and 'codecov/codecov-action@v4'. These are standard components for CI/CD processes on the GitHub platform.
  • [CREDENTIALS_UNSAFE]: Includes a dummy string 'abc123hardcoded' within a section explicitly labeled as a 'Bad CI Configuration' example. This is used for educational purposes to demonstrate an anti-pattern and does not represent a real credential exposure.
  • [PROMPT_INJECTION]: The skill uses instructional markers like '' to define operational boundaries for the agent. These are intended to enforce quality standards during the skill's execution rather than to bypass safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 10:17 PM
Security Audit — agent-trust-hub — ship-infrastructure-ci-cd